Toots for paulasadoorian@infosec.exchange account

Written by Paul Asadoorian on 2025-01-23 at 16:19

Firewalls, VPNs, and network devices require extra scrutiny when it comes to security, given the current threat landscape. New findings from Eclypsium highlight missing and misconfigured security controls (bootloader & UEFI vulns)...Our latest findings are here: https://eclypsium.com/research/pandoras-box-vulns-in-security-appliances/ (including a demo exploit video).

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2025-01-09 at 17:58

In support of Larry and Bill's talk (10am Sunday: Detecting BLE Trackers for the price of a Gas Station Hot Dog) I am bringing some things to Shmoocon this weekend!

=> View attached media | View attached media | View attached media | View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2025-01-08 at 14:18

Who will be at Shmoocon? I will be there and welcome you with open arms :)

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2025-01-07 at 23:16

Bringing in the new year with some fresh research from Eclypsium, this time DNA sequencers are at risk: https://buff.ly/3PqKuwo

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-12-06 at 14:23

On the latest episode of Paul's Security Weekly Bill, Larry and myself discussed "hacker gadgets" including some of our favorite ESP32 and Raspberry PI devices and firmware. Check it out and let us know your favorite hacker gadgets!

Show notes: https://buff.ly/3VqDL92

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-11-05 at 12:40

If you believe you are not a target, attackers are not using UEFI implants and firmware backdoors, then read this: https://eclypsium.com/blog/pacific-rim-chronicling-a-5-year-hacking-escapade/ - The post includes a detailed analysis of the command run by the attackers to deploy a UEFI implant, and an attack demo from my co-worker Mickey!

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-26 at 14:41

MJG did a great job of explaining why some dual-boot systems are unable to boot after MS pushed an SBAT update: https://buff.ly/3YYohvt (The title is amusing) Also, don't just go blaming MS, you should be running up-to-date versions of your bootloaders too.

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-24 at 13:18

Fortune Cookie literally telling me how to live my corporate life

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-23 at 16:02

When the project is on its 3rd lead developer...

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-23 at 13:18

Still fishing for the solution

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-22 at 16:02

So, I need to grow my beard out?

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-22 at 13:18

I knew all that knowledge would come in handy someday! (I actually was a developer on that platform, a long time ago...)

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-21 at 16:02

Jackpot!

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-21 at 13:18

Don't disrupt the flow!

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-20 at 16:02

How many computers have you used that needed this?

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-20 at 13:18

More nerd humor

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-19 at 16:02

It's interesting to see the industry react to the AMD sinkclose vulnerability. The advice is to "patch immediately!", quickly followed by "Well, if you can". Due to the complex supply chain, AMD has to release a fix, and then an OEM has to release a BIOS/UEFI update that in turn updates your AGESA version. Long story short, I have a vulnerable machine and am waiting on the OEM for an update. Eclypsium's product was the best way to determine which version I am running:

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-19 at 13:18

Yet another reason I use Arch BTW

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-18 at 16:02

LOL - Love this

=> View attached media

=> More informations about this toot | View the thread

Written by Paul Asadoorian on 2024-08-18 at 13:18

"This is Mr. Eddie Vedder, from Accounting. I just had a power surge here at home that wiped out a file I was working on. Listen, I'm in big trouble, do you know anything about computers? "

=> View attached media

=> More informations about this toot | View the thread

=> This profile with reblog | Go to paulasadoorian@infosec.exchange account

Proxy Information
Original URL
gemini://mastogem.picasoft.net/profile/109348326583905980
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
360.626517 milliseconds
Gemini-to-HTML Time
6.879793 milliseconds

This content has been proxied by September (3851b).